External cloud, payment and IT suppliers can cause a breach or outage that stops your business trading. Their contracts, SLAs and policies may leave a substantial gap between your loss and recovery.
Supplier-caused loss needs a direct policy trigger
Supplier incidents need the right insuring clause. The supplier must meet the definition of a dependent business.
A dependent business is a firm you directly rely on to trade. It is similar to a key supplier in your supply chain.
Contingent business interruption can pay lost income after a covered event at a direct supplier or customer. Many policies apply waiting periods of 8 to 24 hours.
A short payment-provider outage may harm sales but produce no payment. Check whether suppliers must be named, whether direct dependency is required, and whether non-malicious cloud failure is included.
| Loss after supplier incident | Likely policy section | Common gap |
|---|
| Lost sales during SaaS outage | Contingent business interruption | No direct dependency or waiting period not met |
| Supplier-held personal data exposed | Privacy liability and incident response | Supplier breach excluded or low sub-limit |
| MSP hit by ransomware | System failure, restoration, extortion | Outsourced systems not within the definition |
| Payment processor unavailable | Business interruption or system failure | Utility or provider exclusion |
Vendor contracts rarely pay the full cyber loss
A supplier contract may give you a right to claim. Its liability cap is often far below lost revenue, recovery costs and customer claims.
Service credits are not compensation
An SLA, or service level agreement, commonly gives service credits when uptime falls below target. It rarely gives full compensation.
Credits may equal only days or months of fees. Liability caps are often between 6 and 12 months of fees.
Under UK GDPR and the Data Protection Act 2018, your SME may remain accountable for data it controls. That can apply even where a processor caused the breach.
| Incident | Supplier contract may pay | Your cyber policy may pay | You may retain |
|---|
| Accounting platform data breach | Losses within its cap and indemnity | Forensics, notices and liability if covered | Excess, excluded fines, uninsured loss |
| MSP ransomware | Contract breach, subject to proof | Restoration and interruption if triggered | Loss before waiting period |
Cloud, MSP and payment risks need separate checks
Critical vendors are suppliers whose failure can stop trading or expose personal data. They may initiate payments or give an attacker privileged access.
High-impact suppliers to map first
Cloud providers can cause broad outages. SaaS tools can block orders or records, and payment processors can halt income within minutes.
A managed service provider, or MSP, may hold administrator access to every device. Accounting platforms and AI suppliers may hold payroll, bank or client data.
These risks differ from those posed by a low-cost design tool.
Not every critical supplier creates the same insurance exposure. A cloud outage may stop staff accessing records.
Cover can depend on whether an attack, system failure, or excluded infrastructure event caused the outage. Ransomware affecting a managed service provider can create a wider loss.
An attacker may use the provider's privileged access to encrypt several customer environments. A payment processor outage can stop card sales without compromising data.
A supplier data breach at an accounting platform or AI provider may trigger notification, regulatory and customer-claim costs. Map these outsourced systems separately.
This helps your third-party cyber risk assessment reflect each vendor's service dependency, data and access.
Read definitions before a supplier claim is denied
The schedule shows headline limits. Definitions decide whether a supplier-caused loss fits the policy.
Definitions of supplier, computer system, system failure and business interruption matter. Read these terms before you rely on cover.
Wording checks before renewal
- Confirm whether contingent business interruption covers unnamed suppliers and direct cloud dependencies.
- Check each waiting period, excess and sub-limit for supplier outage, restoration and incident response costs.
- Ask whether human error, software defects and non-malicious system failure are covered.
- Compare the policy limit with the supplier's liability cap and any exclusion for lost profit.
- Check notification deadlines, which may be between 24 and 72 hours in a supplier contract.
A service level agreement liability cap and a cyber policy answer different questions. The contract decides whether the supplier owes compensation.
It usually limits that recovery. The policy decides whether your SME's own loss falls within an insured grant.
For example, privacy liability and incident response cover may pay for notices, legal advice and third-party claims. This may apply after a processor incident.
The supplier may later dispute liability.
Cyber policy exclusions can remove cover for a non-malicious cloud failure. They can also remove cover for an indirect supplier.
An event below the business interruption waiting period may also be excluded. A supplier's indemnity should support your own cover, not replace it.
Align policy limits and supplier duties before renewal
Align the cyber policy, supplier contract and SLA. They should identify the same critical services, security duties, incident contacts and liability limits.
Keep evidence of MFA, tested backups and vendor due diligence. Review arrangements every 6 to 12 months, or after changing a core provider.
This reduces risk. It also gives insurers a clearer account of your controls.
This issue is less relevant where a business has no material reliance on external digital suppliers. It is also less relevant where it does not process business data electronically. It cannot decide whether a live claim will be paid. Cover depends on the full policy wording, facts, notifications, exclusions and the insurer's claims decision.
Insurers increasingly assess whether an SME understands and controls critical vendor dependencies. They do not simply check whether it has antivirus software.
At renewal, a questionnaire may ask about MFA and segregated administrator accounts. It may also ask about offline tested backups, incident-response arrangements and supplier due diligence.
Keep a current vendor register for each critical service. Show the data category, privileged access, alternative provider and contract notification route.
For high-impact suppliers, seek relevant security reports where available. You can also ask for penetration-test summaries or confirmation of their incident process.
These records do not guarantee vendor cyber insurance or claim payment. They help show that declared controls and risk-management practices were accurate at placement and renewal.
Common questions
Does cyber insurance cover a supplier data breach?
It may cover forensic, notification and liability costs. The policy must include supplier-held data and the relevant trigger. UK GDPR duties can still apply to your SME.
Does my supplier's cyber insurance pay my losses?
Usually not directly. You may need to prove contract breach. The supplier's liability cap may limit recovery to 6 to 12 months of fees.
What is contingent business interruption cover?
It covers income lost because a direct supplier or customer suffers a covered cyber event. Policies may have 8-to-24-hour waiting periods. They may exclude indirect suppliers.
Are cloud outages covered by cyber insurance?
They can be covered, but attacks, system failures and utility outages may be treated differently. Check whether the cloud provider is a defined dependent business.
Can an insurer refuse a claim after an MSP breach?
It can dispute cover where the event is excluded, notification was late, or declared controls were materially inaccurate. An MSP breach does not automatically defeat a claim.
What should I ask before buying cyber cover?
Ask about supplier definitions, system failure, contingent business interruption, sub-limits and waiting periods. Compare the answers with your three most important suppliers and their liability caps.